Security Level Estimation and Parameter Optimization Method for Fully Homomorphic Encryption Schemes Based on the LWE Problem

By establishing a security level estimation and parameter optimization model, the problem of parameter selection relying on experience in fully homomorphic encryption schemes is solved, and rapid and automated parameter optimization is achieved. In particular, the communication overhead of BGV and BFV schemes is reduced, improving the efficiency and security of scheme design.

CN120034312BActive Publication Date: 2025-10-31CHONGQING INST OF GREEN & INTELLIGENT TECH CHINESE ACAD OF SCI
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510103458.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-10-31
Estimated Expiration
2045-01-22

AI Technical Summary

Technical Problem

Existing fully homomorphic encryption schemes lack a unified model in the parameter selection process, leading to a reliance on experience in the design process. This makes it difficult to optimize the scheme performance while meeting the user's specified security level, especially the communication overhead problem of BGV and BFV schemes.

Method used

A method for security level estimation and parameter optimization of fully homomorphic encryption schemes based on the LWE problem is established. The security level and optimization parameters are calculated by model (M1) and model (M2) respectively, providing a fast and automated parameter selection scheme suitable for user and platform interaction scenarios.

Benefits of technology

It enables rapid calculation of the security level and optimal parameter setting for the LWE problem, especially providing parameter settings with minimal communication overhead for BGV and BFV schemes, which is suitable for assisting users in security assessment and policy adjustment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034312B_ABST
    Figure CN120034312B_ABST
Patent Text Reader

Abstract

This invention relates to a method for security level estimation and parameter optimization of fully homomorphic encryption schemes based on the LWE problem, belonging to the field of information security. The method includes the following steps: S1: The user provides instructions and parameters; S2: The platform, based on the received instructions, executes step S3 if model (M1) is selected, and step S4 if model (M2) is selected; S3: The platform substitutes the user-specified parameters into model (M1) and solves the model to obtain the security level corresponding to the parameters, then executes S5; S4: The platform substitutes the user-specified values ​​into model (M2) and solves to obtain the optimal values ​​of the scheme parameters, then executes S5; S5: The platform feeds back the calculation results to the user. This invention can quickly calculate the corresponding security level for LWE problems with given parameters. For user-specified security levels and decryption accuracy, it can provide users with parameter settings that minimize communication overhead, and is particularly suitable for assisting users in accurately assessing security and adjusting security strategies when sampling homomorphic encryption schemes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method for estimating the security level and optimizing the parameters of a fully homomorphic encryption scheme based on the LWE problem, and belongs to the field of information security. Background Technology

[0002] The "usable but not visible" nature of data is an effective means of protecting data privacy and provides strong protection for data circulation and in-depth data value mining. As one of the representative technologies, fully homomorphic encryption has gradually become an effective way to implement this method. Currently, almost all fully homomorphic encryption schemes are based on the learning with error (LWE) problem, and the main encryption schemes include BGV[4], BFV[6] schemes, etc. Theoretically speaking, the difficulty of the LWE problem is provable, so the security of fully homomorphic encryption based on the LWE problem is also theoretically guaranteed[1,2]. However, when designing a scheme, it is necessary to select the parameters of the scheme to meet the needs of the actual scenario. This process is usually a trade-off between efficiency and security. Therefore, correctly analyzing and evaluating the difficulty of the LWE problem under different parameter settings has important guiding significance for the parameter selection and scheme design of lattice cryptography schemes.

[0003] Secondly, parameter selection is an unavoidable issue during the solution design process. The goal of parameter optimization is to select the optimal parameter settings to maximize the solution's target performance while meeting the user-specified security level.

[0004] For the problem of estimating the security level of schemes based on the LWE problem, there have been several studies in academia and industry. In particular, Albrecht and his team have comprehensively considered various attack methods against LWE-based encryption schemes and provided a Lattice Estimator for the security level of the scheme[3]. However, the current security analysis software has a relatively complex calculation process and is not conducive to repeated calls. The parameter optimization problem of the scheme can be regarded as the inverse problem of the security level analysis problem of the scheme. Compared with the security level analysis problem of a single index, the parameter selection problem involving different indices is more difficult and has stronger practicality. It can provide direct guidance for scheme design from the user's perspective. However, the parameter selection in the current scheme design process is often based on experience and analysis[5]. As fully homomorphic encryption moves more from the laboratory to the industry, more accurate, optimized and automated parameter selection is undoubtedly necessary.

[0005] Currently, there is no unified model that can describe the parameter optimization problem of all encryption schemes. As the most widely used schemes, BGV and BFV schemes are worth studying in terms of minimizing communication overhead.

[0006] [1]Regev O.On lattices,learning with errors,random linear codes,andcryptography[J].Journal of the ACM(JACM),2009,56(6):34.

[0007] [2]Lyubashevsky,V.,Peikert,C.and Regev,O.,On ideal lattices andlearning with errors over rings.In Annual International Conference on theTheory and Applications of Cryptographic Techniques(pp.1-23).Springer,Berlin,Heidelberg,2010.

[0008] [3]Martin R.Albrecht,Rachel Player and Sam Scott.On the concretehardness of Learning with Errors.Journal of Mathematical Cryptology.Volume 9,Issue 3,Pages 169–203,2015

[0009] [4]Zvika Brakerski,Craig Gentry,and Vinod Vaikuntanathan.“(Leveled)Fully Homomorphic Encryption without Bootstrapping”.In:Proceedings of the 3 rd Innovations in Theoretical Computer Science Conference.ITCS’12.Cambridge,Massachusetts:Association for Computing Machinery,2012,pp.309–325.

[0010] [5] M. Albrecht, M. Chase, H. Chen, J. Ding, S. Goldwasser, S. Gorbunov, S. Halevi, J. Hoffstein, K. Laine, K. Lauter, et al. Homomorphic encryption standard. Protecting privacy through homomorphic encryption, pages 31–62, 2021.

[0011] [6]Fan,J.and Vercauteren,F.,2012.Somewhat practical fully homomorphicencryption.Cryptology ePrint Archive.

[0012] [7]Batnini, H., Michel, C. and Rueher, M., 2005, October. Mind the gaps: A newsplitting strategy for consistency techniques. In International Conference on Principles and Practice of Constraint Programming (pp. 77-91). Berlin, Heidelberg: Springer Berlin Heidelberg. Summary of the Invention

[0013] In view of this, the present invention provides a method for security level estimation and parameter optimization of a fully homomorphic encryption scheme based on the LWE problem, which provides assistance for the evaluation and design of BGV or BFV schemes based on the LWE problem, wherein the LWE problem is as described in reference [1].

[0014] To more clearly describe the method of the present invention, hereby,

[0015] (1) The security level estimation problem of a fully homomorphic encryption scheme based on the LWE problem, with parameters taking the values ​​of key length n, modulus q, and noise parameter α, is modeled as follows (M1):

[0016]

[0017] Where C = 5.46, A = 0.296, B = 20.388,

[0018] (2) The parameter optimization problem (M2) of a fully homomorphic encryption scheme based on the LWE problem with a specified security level λ and decryption accuracy ρ is modeled as follows:

[0019]

[0020] Among them, security level It is a function of the security level; Erf is the Gaussian error function, and k is the variable.

[0021] The application scenarios of this invention involve two parties: users and platforms. Users send their requirements to the platform, and the platform calculates and provides the user with the desired result and returns it to the user.

[0022] For this scenario, the specific steps of the present invention are as follows:

[0023] S1: The user provides instructions and parameters based on the problem to be solved;

[0024] S2: The platform selects the corresponding model (M1) or model (M2) based on the received instructions. If model (M1) is selected, proceed to step S3; if model (M2) is selected, proceed to step S4.

[0025] S3: The platform substitutes the user-specified parameters into the model (M1) and solves the model to obtain the security level corresponding to the parameters, and then executes S5;

[0026] S4: The platform substitutes the user-specified values ​​into the model (M2) and solves it to obtain the optimal values ​​of the scheme parameters, and then executes S5;

[0027] S5: The platform will provide the calculation results back to the user.

[0028] Furthermore, in step S1, the user can choose between "perform security level estimation of the fully homomorphic encryption scheme based on the LWE problem" or "perform parameter optimization of the fully homomorphic encryption scheme based on the LWE problem". If the former is selected, the user needs to provide the parameter values ​​of the LWE problem corresponding to the scheme, that is, the specific values ​​of n, q, and α. If the latter is selected, the user needs to specify the required security level λ and decryption accuracy ρ.

[0029] Furthermore, for parameters n, q, α, the specific steps of step S3 are as follows:

[0030] S301: Construct an expression based on the parameters:

[0031]

[0032] Where δ0 is a function of β, and β is a variable;

[0033] S302: List the single-variable equation Δ=b for β. 2 Given -4ac = 0, solve for all roots of this equation, then round up the largest root to obtain β. m ;

[0034] S303: Set β = β m Substitute the values ​​of a, b, and c into the expression to find the answer. Rounding up gives d m .

[0035] S304: (β,d)=(β) m ,d m Substitute the objective function f(β,d) into the model (M1), and then take the second logarithm of the objective function to obtain the safety level of the scheme.

[0036] Furthermore, regarding the security level λ and decryption accuracy ρ, step S4 specifically comprises:

[0037] S401: The range of values ​​for parameters n, q, α, and k is manually set, and then... Indicates; among which, * represents the upper and lower bounds of the interval for the parameter *, respectively;

[0038] Preferably, I1 is [100, 2000] and I2 is [5000, 10]. 8 ],I3 take [10 -20 10 -5 I4 takes [11,21].

[0039] S402: If Jump to S405; otherwise, let And proceed to the next step; where ← indicates that the value on the right is assigned to the value on the left. Indicates rounding up;

[0040] It is worth noting that we need to determine whether a feasible solution (n,q,α,k) exists in model (M2) satisfying q≤γ. Since directly determining this for model (M2) is difficult, we need to construct model (M3) for transformation. Specifically, model (M3) is as follows:

[0041]

[0042] The values ​​of λ and ρ are the same as in model (M2), and the value of γ is given in S402. If the optimal value of model (M3) is negative, then there exists a feasible solution (n,q,α,k) in model (M2) that satisfies q≤γ; otherwise, there is no feasible solution (n,q,α,k) in model (M2) that satisfies q≤γ.

[0043] S403: Establish the model (M3) and solve for a feasible point where the objective function takes a negative value;

[0044] S404: If step S403 has a solution x * =(n * ,q * ,α * ,k * If x is found, it means that a feasible solution to model (M2) has also been found. * And satisfy q * ≤γ, then let Then proceed to step S402; otherwise, if there is no solution, it means that model (M2) does not have a feasible solution that meets the conditions, then let q ←γ, and jump to step S402;

[0045] S405: If no feasible solution to model (M2) is found, output an empty set, indicating that there are no parameter settings that meet the user's requirements; otherwise, output the feasible solution x of model (M2). * This refers to the optimal parameter selection required by the user.

[0046] Furthermore, the solution process described in step S403 is as follows:

[0047] (1) Initialization: Let Block B = I1 × I2 × I3 × I4, initial activity queue Q = {B};

[0048] (2) Calculate the lower bound of the optimal value: For each block B in Q, take p as the point where all coordinate values ​​in B take the lower bound of the value interval, and calculate the objective function of model (M3). The value at point p is denoted as η(B); if η(B) > 0, then B is removed from Q;

[0049] (3) Block partitioning: Select and take out a block B from Q to minimize the value of η(B), and then divide B into two sub-blocks B1 and B2 of the same size according to the cyclic scheduling strategy, and add B1 and B2 to Q;

[0050] The cyclic scheduling strategy is as shown in reference [7], that is, the value interval of the block is divided into two equal parts in sequence to obtain sub-blocks, so that each value interval is divided into two equal parts once, and then the next cycle is entered, and the sub-blocks are divided into two equal parts in sequence according to the value interval.

[0051] (4) Finding feasible points: For each sub-block B obtained from the division i The feasible point calculation method is used to determine whether a feasible point exists. If it does not exist, the block is discarded, and the feasible value ω(B) is set. iIf the objective function exists, calculate a feasible point and denote the value of the objective function at that point as the feasible value ω(B). i ); where i = 1, 2;

[0052] (5) Determine the sign of the objective function at feasible points: If ω * If the value is less than 0, it means that a feasible point x where the objective function takes a value less than 0 has been found. * The solution process ends here, and the feasible point x is returned. * Otherwise, proceed to the next step; where ω * =min{ω(B1),ω(B2)};

[0053] (6) Determine whether Q is an empty set. If Q is an empty set, it means that no feasible point with the objective function value less than 0 has been found. End the solution process and return to the empty set. If Q is not an empty set, jump to step (2).

[0054] Furthermore, the specific steps of the feasible point calculation method described in step (4) are as follows:

[0055] a) Take block B i Let I1 be two vertices p1 and p2, where vertex p1 corresponds to the lower bound of I1 and the upper bound of I2, I3, and I4; while vertex p2 corresponds to the upper bound of I1, I2, I3, and I4.

[0056] b) Determine whether p1 and p2 are feasible points. If either of them is a feasible point, then a feasible point has been obtained and it is returned; otherwise, proceed to the next step.

[0057] c) Find a feasible point on the line segment connecting p1 and p2 using the midpoint bisection method; if the midpoint is feasible, calculate the feasible value ω(B) of the objective function. i If the midpoint is not a feasible point, repeat this step until the line segment does not contain any points where n is an integer, and then block B is... i

[0058] Discard from Q and let the feasible value ω(B) i ) = +∞.

[0059] The beneficial effects of this invention are as follows: This invention provides a method for estimating the security level and optimizing parameters of fully homomorphic encryption schemes based on the LWE problem. For an LWE problem with given parameters, its corresponding security level can be calculated quickly. For LWE-based BGV and BFV schemes, for user-specified security levels and decryption accuracy, it can provide users with parameter settings that minimize communication overhead; it is particularly suitable for assisting users in accurately assessing security and adjusting security strategies when sampling homomorphic encryption schemes. Attached Figure Description

[0060] To illustrate the objectives and technical solutions of this invention, the following figures are provided:

[0061] Figure 1 This is a framework diagram of the method of the present invention;

[0062] Figure 2 This is a flowchart of the model (M2) solution process in the method of this invention;

[0063] Figure 3 This is a flowchart illustrating a feasible point where the objective function of the solution model (M3) takes a negative value in the method of this invention. Detailed Implementation

[0064] When analyzing and designing fully homomorphic encryption schemes based on the LWE problem, security level assessment and parameter optimization are required. In a user-platform dual-side scenario, the user sends instructions to the platform according to actual needs, and the platform selects either model (M1) or model (M2) based on the instructions, solves the problem, and then feeds back the results to the user. The following provides implementation examples for these two user needs: security level assessment and parameter optimization of fully homomorphic encryption schemes based on the LWE problem.

[0065] Example 1:

[0066] Suppose user "Zhang San" wants to evaluate the security level of a fully homomorphic encryption scheme based on the LWE problem. Assume the parameters of the existing scheme are n = 128, q = 16411, and α = 0.00180384. This invention provides a "security level estimation method for fully homomorphic encryption schemes based on the LWE problem," combining... Figure 1 The preferred embodiments of the present invention will now be described in detail.

[0067] The specific steps are as follows:

[0068] Step 1: Zhang San provides a security level evaluation instruction for a fully homomorphic encryption scheme based on the LWE problem, and provides the parameters n=128, q=16411, α=0.00180384.

[0069] Step 2: The platform selects the (M1) model according to the instructions.

[0070] Step 3: The platform substitutes the parameters n=128, q=16411, α=0.00180384 provided by Zhang San into the model (M1) and solves the model. The specific solution steps are as follows:

[0071] (3-1) Constructing the expression

[0072]

[0073] Here, a, b, and c are all single-variable expressions in terms of β.

[0074] (3-2) List the single-variable equation Δ=b in β. 2 Given -4ac = 0, solve for all roots of this equation, then round up the largest root to obtain β. m =101.

[0075] (3-3) Substitute β = 101 into the expressions for a, b, and c to find the answer. Rounding up gives d m =361.

[0076] (3-4) Substitute (β,d)=(101,361) into the objective function in model (M1), and then take the 2 logarithm of the objective function to obtain the safety level of the scheme, which is 58.4.

[0077] Step 4: The platform returns the security level assessment results of the solution to Zhang San.

[0078] Example 2:

[0079] Suppose user "Zhang San" wants to optimize the parameters of a fully homomorphic encryption scheme based on the LWE problem. Further assume that Zhang San's scheme requires a security level of λ = 80 and ρ = 1-2. -100 This invention provides a "parameter optimization method for a fully homomorphic encryption scheme based on the LWE problem".

[0080] The following is in conjunction with the appendix Figure 1 The preferred embodiments of the present invention will be described in detail below.

[0081] Step 1: Zhang San provides parameter optimization instructions for a fully homomorphic encryption scheme based on the LWE problem, and provides parameters λ = 80, ρ = 1-2. -100 .

[0082] Step Two: Combining Figure 2 The platform selects the (M2) model based on the instructions:

[0083]

[0084] Step 3: The platform will use the parameters λ = 80 and ρ = 1-2 provided by Zhang San. -100 Substitute the values ​​into the model (M2) and solve the model. The specific solution steps are as follows:

[0085] (3-1) The range of values ​​for parameters n, q, α, and k is set manually:

[0086] I1=[100,2000], I2=[5000,10 8 ],I3=[10 -20 10 -5],I4=[11,21。

[0087] (3-2)Judgement Is it true or false: Currently q =5000, The above inequality is false. Let

[0088] (3-3) Combination Figure 3 Build a model And find a feasible point where the objective function takes a negative value;

[0089] Furthermore, the specific steps to solve (M3) are as follows:

[0090] (1) Initialization: Let make B = I1 × I2 × I3 × I4. Let the initial activity queue Q = {B};

[0091] (2) Calculate the lower bound of the optimal value: Currently, Q only contains B. Let p be the point in B where all coordinate values ​​take the lower bound of their respective intervals, i.e., p = (100, 5000, 10...). -2 Then, the objective function of model (M3) at p is calculated to be -3.1415.

[0092] (3) Block partitioning: Take B from Q. Then, divide B into two equal sub-blocks B1 and B2 according to the round-robin scheduling strategy, and add B1 and B2 to Q; where B1 = I′1×I2×I3×I4 and B2 = I″1×I2×I3×I4, where I′1 = [100,1050] and I″1 = [1050,2000];

[0093] (4) Finding feasible points: For each sub-block B obtained from the division i The feasible point calculation method is used to determine whether a feasible point exists. If it does not exist, the block is discarded, and the feasible value ω(B) is set. i If the objective function exists, calculate a feasible point and denote the value of the objective function at that point as the feasible value ω(B). i ); where i = 1, 2;

[0094] Furthermore, the specific steps of the feasible point calculation method described in step (4) are as follows:

[0095] a) Take block B i Let I1 be two vertices p1 and p2, where vertex p1 corresponds to the lower bound of I1 and the upper bound of I2, I3, and I4; while vertex p2 corresponds to the upper bound of I1, I2, I3, and I4.

[0096] b) Determine whether p1 and p2 are feasible points. If either of them is a feasible point, then a feasible point has been obtained and it is returned; otherwise, proceed to the next step.

[0097] c) Find a feasible point on the line segment connecting p1 and p2 using the midpoint bisection method; if the midpoint is feasible, calculate the feasible value ω(B) of the objective function. i If the midpoint is not a feasible point, repeat this step until the line segment does not contain any points where n is an integer, and then block B is... i Discard from Q and let the feasible value ω(B) i ) = +∞.

[0098] Using the above method, feasible points n = 575, q = 50002500, α = 0.00001, and k = 21 were found in block B1. The objective function value at this point was calculated to be 3.98, i.e., ω(B1) = 3.98. The same operation was performed on block B2, resulting in feasible points n = 1775, q = 50002500, α = 0.00001, and k = 21. The objective function value at this point was 9.37, i.e., ω(B2) = 9.37.

[0099] d) Determine the sign of the objective function at feasible points: Let ω * =min{ω(B1),ω(B2)}. Yes * >0, therefore no feasible point was found where the objective function of model (M3) takes a value less than 0.

[0100] e) Determine if Q is an empty set: Q = {B1, B2} is not an empty set, jump to (2).

[0101] (3-4) Step (3-3) has a solution x * =(575,12650325,7.0084*10) -6 ,21), indicating that an equivalent feasible solution to model (M2) has been found with a corresponding q value of 12650325, which is less than γ, so let Then proceed to step (3-2).

[0102] (3-5) When When the above loop terminates, the optimal feasible solution is found to be {n = 258, q = 44822, α = 0.000358360, k = 12.0131}. This is the optimal parameter selection required by the user.

[0103] Finally, it should be noted that the above preferred embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail through the above preferred embodiments, those skilled in the art should understand that various changes can be made to it in form and detail without departing from the scope defined by the claims of the present invention.

Claims

1. A method for security level estimation and parameter optimization of a fully homomorphic encryption scheme based on the LWE problem, targeting both users and platforms, wherein the user sends their requirements to the platform, and the platform calculates and returns the desired result to the user; characterized in that, Includes the following steps: S1: The user provides instructions and parameters based on the problem to be solved; S2: The platform selects the corresponding model M1 or model M2 according to the received instructions; if model M1 is selected, proceed to step S3. If model M2 is selected, proceed to step S4; S3: The platform substitutes the user-specified parameters into model M1 and solves the model to obtain the security level corresponding to the parameters, and then executes S5; S4: The platform substitutes the user-specified values ​​into model M2 and solves the problem to obtain the optimal values ​​of the scheme parameters, and then executes S5; S5: The platform will provide the calculation results to the user; In step S1, the user can choose between two instructions: "Perform security level estimation of the fully homomorphic encryption scheme based on the LWE problem" or "Perform parameter optimization of the fully homomorphic encryption scheme based on the LWE problem". If the former is selected, the user needs to provide the parameter values ​​of the LWE problem corresponding to the scheme, namely the specific values ​​of key length n, modulus q, and noise parameter α. If the latter is selected, the user needs to specify the required security level λ and decryption accuracy ρ. For the security level estimation problem of fully homomorphic encryption schemes based on the LWE problem with parameters n, q, and α, model M1 is established as follows: Where C = 5.46, A = 0.296, B = 20.388, β is a variable; For a given security level λ and decryption accuracy ρ, the parameter optimization problem of a fully homomorphic encryption scheme based on the LWE problem is modeled as follows: Among them, security level It is a function of the safety level; θ(k)=1-Erf(k / √2), where Erf is the Gaussian error function and k is a variable.

2. The method for security level estimation and parameter optimization of a fully homomorphic encryption scheme based on the LWE problem according to claim 1, characterized in that, The specific steps of step S3 are as follows: S301: Construct an expression based on the parameters: Where δ0 is a function of β, and β is a variable; S302: List the single-variable equation Δ=b for β. 2 Given -4ac = 0, solve for all roots of this equation, then round up the largest root to obtain β. m ; S303: Set β = β m Substitute the values ​​of a, b, and c into the expression to find the answer. Rounding up gives d m ; S304: (β,d)=(β) m ,d m Substitute the objective function f(β,d) into model M1, and then take the second logarithm of the objective function to obtain the safety level of the scheme.

3. The method for security level estimation and parameter optimization of a fully homomorphic encryption scheme based on the LWE problem according to claim 1, wherein step S4 specifically comprises: S401: The range of values ​​for parameters n, q, α, and k is manually set, and then... Indicates; among which, * These represent the upper and lower bounds of the interval for the parameter *, respectively. S402: If Jump to S405; otherwise, let And proceed to the next step; where ← indicates that the value on the right is assigned to the value on the left. Indicates rounding up; S403: Establish model M3 and solve for a feasible point where its objective function takes a negative value; S404: If step S403 has a solution x * =(n * ,q * ,α * ,k * If x is found, it means that a feasible solution to model M2 has also been found. * And satisfy q * ≤γ, then let Then proceed to step S402; otherwise, if there is no solution, it means that model M2 does not have a feasible solution that meets the conditions, then let q ←γ, and jump to step S402; S405: If no feasible solution is found for model M2, output an empty set, indicating that there are no parameter settings that meet the user's requirements; otherwise, output a feasible solution x for model M2. * This refers to the optimal parameter selection required by the user. The model M3 mentioned above is:

4. The method for security level estimation and parameter optimization of a fully homomorphic encryption scheme based on the LWE problem according to claim 3, characterized in that, In step S401, I1 is set to [100, 2000], and I2 is set to [5000, 10]. 8 ], I3 takes [10 -20 10 -5 I4 takes [11,21].

5. The method for security level estimation and parameter optimization of a fully homomorphic encryption scheme based on the LWE problem according to claim 3, characterized in that, The solution process described in step S403 is as follows: (1) Initialization: Let Block B = I1 × I2 × I3 × I4, initial activity queue Q = {B}; (2) Calculate the lower bound of the optimal value: For each block B in Q, take p as the point where all coordinate values ​​in B take the lower bound of the value interval, and calculate the objective function of model M3. The value at point p is denoted as η(B); if η(B) > 0, then B is removed from Q; (3) Block partitioning: Select and take out a block B from Q to minimize the value of η(B), and then divide B into two sub-blocks B1 and B2 of the same size according to the cyclic scheduling strategy, and add B1 and B2 to Q; (4) Finding feasible points: For each sub-block B obtained from the division i The feasible point calculation method is used to determine whether a feasible point exists. If it does not exist, the block is discarded, and the feasible value ω(B) is set. i If the objective function exists, calculate a feasible point and denote the value of the objective function at that point as the feasible value ω(B). i ); where i = 1, 2; (5) Determine the sign of the objective function at feasible points: If ω * If the value is less than 0, it means that a feasible point x where the objective function takes a value less than 0 has been found. * This concludes the solution process, and the feasible point x is returned. * Otherwise, proceed to the next step; where ω * =min{ω(B1),ω(B2)}; (6) Determine whether Q is an empty set. If Q is an empty set, it means that no feasible point with the objective function value less than 0 has been found. End the solution process and return to the empty set. If Q is not an empty set, jump to step (2).

6. The method for security level estimation and parameter optimization of a fully homomorphic encryption scheme based on the LWE problem according to claim 5, characterized in that, The specific steps of the feasible point calculation method described in step (4) are as follows: a) Take block B i Let I1 be two vertices p1 and p2, where vertex p1 corresponds to the lower bound of I1 and the upper bound of I2, I3, and I4; while vertex p2 corresponds to the upper bound of I1, I2, I3, and I4. b) Determine whether p1 and p2 are feasible points. If either of them is a feasible point, then a feasible point has been obtained and it is returned. Otherwise, proceed to the next step; c) Find a feasible point on the line segment connecting p1 and p2 using the midpoint bisection method; if the midpoint is feasible, calculate the feasible value ω(B) of the objective function. i ); If the midpoint is not a feasible point, repeat this step until the line segment does not contain any points where n is an integer, and then move block B. i Discard from Q and let the feasible value ω(B) i ) = +∞.

Citation Information

Patent Citations

  • Non-interactive naive Bayesian classification method based on homomorphic encryption

    CN114037013A

  • Security evaluation method of password scheme based on LWE problem design

    CN117792644A